Stored Cross-Site Scripting in Table Field Add-on for WordPress Plugin
CVE-2025-12067
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 January 2026
What is CVE-2025-12067?
The Table Field Add-on for the Advanced Custom Fields (ACF) and Simple Custom Fields (SCF) plugins for WordPress is susceptible to Stored Cross-Site Scripting due to insufficient input sanitization and output escaping. This vulnerability allows unauthorized authenticated users with Author-level access and above to inject malicious web scripts into table cell content. As a result, any user accessing the manipulated pages might unknowingly execute these scripts, leading to potential data theft and further exploitation of site vulnerabilities.
Affected Version(s)
Table Field Add-on for ACF and SCF 0 <= 1.3.30